CVE-2026-101009: aaPanel BaoTa Unzip panelTask.py panelTask.bt_task._unzip os command injection
A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected element is the function panelTask.bttask.unzip of the file /www/server/panel/class/panelTask.py of the component Unzip Handler. Executing a manipulation of the argument Password can lead to os command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which installations should be investigated first?
aaPanel BaoTa installations running version 11.8.0 or earlier should be treated as potentially affected. The supplied data does not identify a fixed version.
What conditions does exploitation require?
The attack can be initiated remotely, but the CVSS vector indicates that the attacker needs high privileges and user interaction. The vulnerable input is the Password argument handled by the unzip functionality.
How urgent is remediation?
The issue is rated high severity with a CVSS score of 8.4, and a public exploit disclosure exists. Prioritize investigation and remediation of exposed, privileged aaPanel environments.